Earlier quoted context omitted.
How do you think they're decrypting in real time? I have no idea how they're doing it. But I believe it can be done simply because the intelligence agencies have the best, largest, fastest, most advanced machines that money can buy. Machines that none of us have even heard of, that are years ahead of anything any of us will ever touch in our lifetimes.
Back of the envelope, to see scale: to brute force SHA-256 you need to try about 2^255 combinations, so you'd need to have 2^194x (1,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000x) the hashpower of the Bitcoin network (80 EH/s). If you told me you thought they had cracked a common algorithm so they could do it in only 2^60 time that would at least be plausible. But the idea that they…
South African authorities admit to mass surveillance
61–70 of 145 posts
Re: South African authorities admit to mass surveillance
#62Earlier quoted context omitted.
Back of the envelope, to see scale: to brute force SHA-256 you need to try about 2^255 combinations, so you'd need to have 2^194x (1,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000x) the hashpower of the Bitcoin network (80 EH/s). If you told me you thought they had cracked a common algorithm so they could do it in only 2^60 time that would at least be plausible. But the idea that they…
I said nothing about brute forcing.
Re: South African authorities admit to mass surveillance
#63Earlier quoted context omitted.
if they don't have the expertise, someone else with the expertise interested in access to the data will help them.
It's surprising to me at least because South Africa has a GDP per capita of $~6.1k, and perhaps can't afford access to that expertise. Which I suppose suggests that they didn't pay for it, and another nation state 'helped out' via intermediaries.
Re: South African authorities admit to mass surveillance
#64> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.
I can imagine a sustainable business could be made operating a fleet of ships in international waters that pick up undersea cables, taps them, and uplinks the data in real time to whichever .gov subscribes to it. The company taking the risk gets a big fat government check every month, and the governments get to deny they're tapping anyone's data.
It's not easy to tap submarine fibre optic cables. The US Navy has a Nuclear Sub dedicated to the task. You can't just pick them up and stick a tap in them.
Re: South African authorities admit to mass surveillance
#65> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.
I can imagine a sustainable business could be made operating a fleet of ships in international waters that pick up undersea cables, taps them, and uplinks the data in real time to whichever .gov subscribes to it. The company taking the risk gets a big fat government check every month, and the governments get to deny they're tapping anyone's data.
Re: South African authorities admit to mass surveillance
#66Earlier quoted context omitted.
>> Linux users currently have the lowest when using Chrome with 86%. I'm curious why the is. They probably browse quite a few old sites for documentation and tooling that are just not updated for HTTPS. A forum I post on to this day is still served over plain ole HTTP and they have no interest in changing.
Isn’t it more likely to be low grade android devices in poor countries with outdated government, banking, and education portals? I doubt kernel hackers make up a large enough demographic to skew the metrics...
A lot of popular Linux and developer related pages are HTTP only. I did a quick Google search for some Linux related tasks, and found plenty of sites that don't use HTTPS. e.g. man7.org, linuxhowtos.org, linuxcommand.org
The report does break down HTTPS traffic by country, and you're right that lower income countries do have a lower share of HTTPS traffic.
Re: South African authorities admit to mass surveillance
#67The German BND snoops traffic at DECIX. UK snoops on transatlantic cables. Everyone snoops. Either we move to full e2e encryption or we organize democratically to tear down the modern Stasi.
Re: South African authorities admit to mass surveillance
#68The German BND snoops traffic at DECIX. UK snoops on transatlantic cables. Everyone snoops. Either we move to full e2e encryption or we organize democratically to tear down the modern Stasi.
Re: South African authorities admit to mass surveillance
#69> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.
> I can’t understand how this news would surprise anyone I tried to tell my family about the Snowden leaks and the implications just a year ago. They are all university educated people. They categorically did not believe that what I was saying was real, and when I showed them all the leaks they did not believe the content was true. Billions of people simply don't believe it's true.
Re: South African authorities admit to mass surveillance
#70Earlier quoted context omitted.
I said nothing about brute forcing.
That's how I read being able to do it because you have "the best, largest, fastest, most advanced machines that money can buy".
Seeing this photo makes me think that's more likely.
https://blog.encrypt.me/assets/img/posts/2013/11/05/nsa_slid...
Pardon the source but I'm on mobile.